nerdexam
Cisco

200-201 · Question #482

A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further isolation actions. According to NIST.SP800-61, in which phase of incident response is this action

The correct answer is B. detection and analyze phase. The phases of incident response according to NIST.SP800-61 are: Detection and Analysis Containment, Eradication, and Recovery Post-Incident Activity During the detection and analysis phase, SOC teams monitor systems for signs of incidents using various tools (like the Cisco Firep

Submitted by tarun92· Mar 6, 2026Security Policies and Procedures

Question

A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further isolation actions. According to NIST.SP800-61, in which phase of incident response is this action?

Options

  • Apost-incident activity phase
  • Bdetection and analyze phase
  • Cpreparation phase
  • Deradication and recovery phase

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    80% (20)
  • C
    4% (1)
  • D
    4% (1)

Explanation

The phases of incident response according to NIST.SP800-61 are: Detection and Analysis Containment, Eradication, and Recovery Post-Incident Activity During the detection and analysis phase, SOC teams monitor systems for signs of incidents using various tools (like the Cisco Firepower Manager). This is where they detect threats, investigate suspicious activity, and plan actions such as isolating compromised systems. This phase involves collecting and reviewing data, determining the scope of the incident, and deciding on initial response actions like isolation.

Topics

#NIST SP 800-61#incident response#security operations#detection and analysis

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice